US11539726B2

System and method for generating heuristic rules for identifying spam emails based on fields in headers of emails

Summary by NHIP

Spam Email Heuristic Rule Generation

The system collects email statistical data and groups messages into clusters based on header fields and hyperlinks. It generates hashes from frequent data combinations and formulates regular expressions based on hyperlink lengths to create spam identification rules.

Claim Score by NHIP

Read claim 9, the broadest

Abstract

Disclosed herein are systems and methods for generating heuristic rules for identifying spam emails based on fields in headers of emails. In one aspect, an exemplary method comprises, collecting statistical data on contents of a plurality of emails; analyzing the statistical data to identify different types of content, including headers or hyperlinks in said emails; grouping the emails into clusters based on types of content identified in said emails, wherein at least one cluster group being based on fields in headers of said emails; generating a hash from the most frequent combination of group of data in each cluster; formulating regular expressions based on analysis of hyperlinks of emails corresponding to the generated hashes; and generating heuristic rule for identifying spam emails by combining the hashes and the corresponding regular expressions, wherein the hash is generated based on fields in the headers of said emails.

US11539726B2, drawing sheet 1
Sheet 1 of 6

Term

12.8 yearsleft in the term

Expires 17 July 2039.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

20 claims: 3 independent, 17 dependent

  1. 1
    A method for generating heuristic rules for identifying spam emails based on fields in headers of emails, the method comprising:collecting, by a processor, statistical data on contents of a plurality of emails;analyzing, by the processor, the collected statistical data to identify different types of content of said emails, including one or more of headers or hyperlinks in said emails;grouping, by a processor, the plurality of emails into one or more clusters based on the different types of content identified in said emails, wherein at least one cluster includes one or more groups based on fields in headers of said emails;selecting, by the processor, at least one most frequent combination of groups of data in each cluster;generating, by the processor, a hash from the at least one most frequent combination of groups;formulating, by the processor, at least one regular expression based on an analysis of hyperlinks of the emails corresponding to the generated hashes;and generating, by the processor, at least one heuristic rule for identifying spam emails by combining at least one hash and the corresponding regular expression, wherein the at least one hash is generated based on fields in the headers of said emails.
  2. 9
    Broadest claimClaim Score 43, average(NHIP)A system for generating heuristic rules for identifying spam emails based on fields in headers of emails, comprising:at least one processor configured to: collect statistical data on contents of a plurality of emails;analyze the collected statistical data to identify different types of content of said emails, including one or more of headers or hyperlinks in said emails;group the plurality of emails into one or more clusters based on the different types of content identified in said emails, wherein at least one cluster includes one or more groups based on fields in headers of said emails;select at least one most frequent combination of groups of data in each cluster;generate a hash from the at least one most frequent combination of groups;formulate at least one regular expression based on an analysis of hyperlinks of the emails corresponding to the generated hashes;and generate at least one heuristic rule for identifying spam emails by combining at least one hash and the corresponding regular expression, wherein the at least one hash is generated based on fields in the headers of said emails.
  3. 17
    A non-transitory computer readable medium storing thereon computer executable instructions for generating heuristic rules for identifying spam emails based on fields in headers of emails, including instructions for:collecting, by a processor, statistical data on contents of a plurality of emails;analyzing, by the processor, the collected statistical data to identify different types of content of said emails, including one or more of headers or hyperlinks in said emails;grouping, by a processor, the plurality of emails into one or more clusters based on the different types of content identified in said emails, wherein at least one cluster includes one or more groups based on fields in headers of said emails;selecting, by the processor, at least one most frequent combination of groups of data in each cluster;generating, by the processor, a hash from the at least one most frequent combination of groups;formulating, by the processor, at least one regular expression based on an analysis of hyperlinks of the emails corresponding to the generated hashes;and generating, by the processor, at least one heuristic rule for identifying spam emails by combining at least one hash and the corresponding regular expression, wherein the at least one hash is generated based on fields in the headers of said emails.